A vulnerability marked as critical has been reported in Supsystic Pricing Table 1.8.6/1.8.7 . Affected by this vulnerability is the function getListForTbl of the component GET Parameter Handler . This manipulation of the argument sidx causes sql injection. This vulnerability is registered as CVE-2020-37243 . Remote exploitation of the attack is possible. Furthermore, an exploit is available.